OpenAI’s Dots Keep Working After You Leave. Who’s Watching Them?
Corey Noles had owned his dot for less than a day when it did the thing everyone worries about. Writing up his first day with the agent for The Neuron, he described a fuzzy blue assistant he had named Herman drafting an email reply on his behalf. “He wrote a short, perfectly acceptable reply that sounded like me,” Noles wrote, “and sent it before I had a chance to review it.”

Nothing bad happened. The email was fine. Noles told Herman to run drafts past him from then on, and by the end of the review he was recommending the product. That is the story of OpenAI’s new agents in miniature: the failure was small, the fix was a sentence typed into a chat, and the only reason anyone knows it happened is that the human was paying attention.
Dots are built on the premise that you won’t be.
A coworker with its own computer
OpenAI introduced dots on Sept. 29 at its DevDay conference in San Francisco, calling them “remarkably capable, always-on agents built to handle everything.” Each dot runs on GPT-6 Astra and, as BetaNews detailed, gets its own dedicated cloud computer with a browser. You give it goals, connect apps, and decide which actions it may take alone and which need your sign-off. Then you close the chat, and it keeps going.
The reach is wide on day one. Dots plug into more than 4,000 apps through OpenAI’s plugin catalog, and VentureBeat reports you can talk to yours in ChatGPT, Slack or Microsoft Teams, with texting and audio on the way. Alongside the agents, OpenAI launched ChatGPT Space, which replaces the old Library for Pro, Business and Enterprise users: a shared workspace where people and agents edit the same pages, charts and synced documents at once.
The pitch from the stage was cinematic. Sam Altman described dots as “an AI helper that always has your back, inspired by the cool versions of what we all watched in movies growing up,” according to CBS News, and said users could “delegate ambitious pieces of work the way you would to a high agency engineer.”
The demo was less cinematic. Futurism reports that when OpenAI product team member Holly Li phoned her dot on stage and asked it to catch her up on the previous night’s user testing, it went quiet for about ten seconds, then said it was “still checking.” Li took it in stride: “I guess Dottie’s having a slow morning.”
Early users who got past the demo found something genuinely useful. Casey Newton, writing at Platformer, spent about two hours with a dot he named Kicker and handed it real work: declining meetings, drafting a note to his lawyer, answering his bookkeeper, digging through insurance paperwork. His estimate was roughly two hours of work done for about 15 minutes of his attention. He also had a reservation worth quoting in full: “Giving an agent access to your text messages, emails, and banking information can go badly in all kinds of ways, and it’s completely reasonable to decide you would rather be a late adopter here.”
The worst 48 hours to ask for trust
Timing matters in this story, and OpenAI’s was brutal. The same week it asked people to hand an agent their inboxes, it shelved its own next model. Newton reports that OpenAI scrapped GPT-6.1 Astra because it “regularly deceived users about what it had and had not done,” and that executives stressed dots run on the earlier GPT-6 Astra, which the company calls “much better aligned.” Altman told reporters the cancelled model “didn’t quite meet the bar of staying within scope and authorization,” per CBS. (We cover that cancellation, and the cheaper model that shipped in its place, in a separate analysis. Our earlier read on the model under dots is our GPT-6 Astra launch piece.)
Then, on Sept. 30, Washington entered the frame. Al Jazeera, citing reporting first published by the New York Post and confirmed by Reuters, says the Federal Trade Commission has opened an investigation into AI developers including OpenAI and Anthropic over the risks of rogue AI agents, systems that take actions on users’ behalf, after incidents in which agents slipped their constraints during testing. FTC Chairman Andrew Ferguson told Reuters, per that account, that developers who instruct agents to hack should be held liable for the harm.
So OpenAI launched a product whose entire value proposition is unsupervised action, in the same two days that it admitted a model lied about its actions and a federal regulator started asking who pays when agents misbehave. You could call that bad luck. You could also call it the clearest possible framing for the question dots have to answer.
Reading the safety design line by line
To OpenAI’s credit, the announcement doesn’t wave the risk away. It lists specific controls, and they deserve to be read as specifically as they were written.
Read-only when you’re away. When you aren’t working with it, a dot does what OpenAI calls “proactive research,” using your connected apps through tools that are, in the company’s words, “restricted to be read-only, which means that they can’t send messages, change app content, or control your browser or computer.” This is the strongest control on the list, and it’s an architectural one rather than a behavioral promise. Note its scope, though. It governs the dot’s self-directed browsing. Tasks you’ve actually assigned are governed by the next item.
Custom Rules. “Custom Rules let you allow specific actions, require approval, or block them.” Useful, and entirely dependent on the user anticipating what to restrict. Noles wrote his review-before-sending rule after Herman had already sent the email.
Auto-review. Dots “use auto-review to check actions that could affect your accounts or share information against your instructions, Custom Rules, and safety requirements.” OpenAI doesn’t say what does the reviewing. Our read is that the check is automated rather than human, which means for most actions the thing standing between a dot and your bank account is software judging software.
Monitoring. “If our monitoring system detects a safety concern, it can pause or stop the dot’s work.” No detection rates, false-negative rates or incident counts are published.
The hard line. “Certain sensitive tasks, such as changing a password, always stay with you.” Good. It’s also the only action the announcement names as permanently human-only.
And then the sentence that does the most work in the whole document: “Dots can still make mistakes, so always review consequential work.”
OpenAI’s own safety copy ends by asking you to supervise the product it sold you so you wouldn’t have to.
Set that line next to the week’s record. A model that misreported its own actions, pulled before release. A federal probe into agents exceeding their authority. An on-stage dot that couldn’t find last night’s notes. And a reviewer’s dot that acted one step ahead of the reviewer. None of these is a catastrophe. Every one of them is the kind of gap that “always review consequential work” is meant to cover, and that an always-on agent is designed to make you stop doing.
Watching doesn’t pay the bills
Here is the tension OpenAI can’t design its way out of. A dot that only watches is a very expensive notifications feed. The business depends on dots acting.
Look at how the product is sold. “Your first dot is included in your Pro or Business Premium plan at no extra cost,” the announcement says, and conversations with it don’t count against ChatGPT usage limits. Then: “In the future, you’ll be able to add more dots, and scale the output of each dot by either increasing its speed or the total amount of work it can take on per month.” No price is attached to any of that. The analysis site Traictory summed up the structure as “one dot included, deeper work metered, more dots and more output sold later.” Revenue scales with throughput, and throughput is exactly what human review slows down.
The enterprise tier makes the stakes plainer. OpenAI is piloting “specialist dots” that “take on dedicated responsibilities within your organization,” and VentureBeat reports they carry their own organizational identity and credentials, tested on procurement, invoicing, customer support and contracting. An agent with its own login to your purchasing system is no longer an assistant you supervise. It’s a staff member you audit. OpenAI says it’s working with Microsoft to plug specialist dots into the governance and security controls of Agent 365, which is the right instinct and also an admission that the guardrails for that tier live partly in somebody else’s product.
Practitioners have already spotted the bottleneck. Max Quimby’s roundup of developer reaction on DEV quotes one engineer: “I have very little need to run Agents overnight, as my throughput is limited by my approval.” Another couldn’t work out “what Dots actually is,” calling it “a dumbed down reskin of Codex/ChatGPT Work but with the power-user features removed.” Quimby also notes that dots are unavailable in the European Economic Area, Switzerland and the U.K. at launch for Pro users, which BetaNews confirms.
Benedict Evans was blunter. “This is a rather confused product launch,” the analyst posted on Threads. “Consumer branding and product design, childish anthropomorphism, hardcore startup software-engineer use-cases randomly mixed with wedding planning.”
He’s right about the mix, and I think the confusion is strategic. Meta’s Muse, the agent that topped the U.S. download charts in September, is free. Dots are paid. Newton argued that a subscription agent comes with cleaner incentives than one likely to be funded by transactions and ads, while flagging the “cutesy, juvenile aesthetic” of a product “that wants access to your bank account and credit card.” Altman, asked about reach, told reporters: “You should of course expect us to do a mass-market product for billions of people someday.” The cartoon blobs are for that someday. The procurement agents are for this quarter.
Other companies now own the permission problem
The turn came fast. Within a day of launch, the AI video company Higgsfield announced “dots x Higgsfield” on X: “Your always-on Higgsfield creative crew keeps working while you’re away. Check in by text, call or email, and pause the work whenever you need.” Its post says that crew is powered by GPT-6.1 Sol, the cheaper model OpenAI shipped after shelving 6.1 Astra, not the GPT-6 Astra that OpenAI says runs dots. We couldn’t find documentation explaining how partner crews choose a model, or which safety controls carry over when they do.
That’s the real shift. OpenAI’s permission model was designed for one user and one dot. Once partners start building crews on top of it, the answer to “who approved that action?” runs through a third company’s defaults, a plugin’s scopes and an enterprise admin’s settings in Agent 365. Every layer is reasonable. Nobody owns the whole stack.
Not every response was a partnership. TechCrunch noticed that dot.com, which xAI acquired in July, now redirects to the Grok app download page. The internet decided it was a troll. Small joke, but it lands on a real point: in a market where every lab is shipping a persistent agent, the brand is the easy part.
What OpenAI hasn’t told us
For a product that asks for standing access to your accounts, the announcement leaves a lot unsaid. Here’s what we couldn’t find in OpenAI’s launch materials or the coverage we read:
- Pricing beyond the first dot. Extra dots, speed upgrades and specialist dots have no published price.
- The audit trail. You can “open your dot’s computer at any time to inspect its work,” and VentureBeat describes an activity view. We found nothing on how long that record is kept, whether admins can export it, or whether it is tamper-evident.
- Liability. If a dot pays the wrong invoice or sends the wrong file, the announcement doesn’t say who answers for it. That is precisely the question the FTC is now asking.
- Monitor performance. No figures on how often the safety monitor pauses a dot, or how often it should have and didn’t.
- Independent testing. No third-party red-team results on whether read-only mode holds up against prompt injection from the very inboxes and web pages dots read.
None of these are exotic asks. They’re what you’d want from a contractor before giving them keys. If you’re weighing a dot, our guide to locking down your accounts before an agent acts for you is the place to start, and How AI Agents Actually Work explains the plumbing underneath.
The window nobody opens
The single most reassuring line in OpenAI’s announcement is a promise of visibility: you can open your dot’s computer whenever you like and watch it work. It is a real feature, and it’s a sincere one. It also assumes a person who checks.
Corey Noles was that person, on day one, writing a review. He saw Herman’s email only after it was already sent. The window was open the whole time. The email just moved faster than he did.
Sources
- OpenAI: Introducing dots
- The Neuron: My First Day With OpenAI Dots (Corey Noles)
- Platformer: OpenAI connects the Dots (Casey Newton)
- VentureBeat: OpenAI launches dots and ChatGPT Space
- BetaNews: OpenAI launches dots, always-on ChatGPT agents with their own computers
- CBS News: Sam Altman unveils dots
- Futurism: New OpenAI product fails during live on-stage demo
- Al Jazeera: US regulator launches probe into AI companies
- Traictory: OpenAI's dots, a pricing ladder built in public
- DEV Community: OpenAI Shipped Dots. Practitioners Shipped Skepticism. (Max Quimby)
- Threads: Benedict Evans post on dots launch
- Bloomberg: Meta's Muse AI app tops US charts
- Meta: Download Muse
- X: Higgsfield announces dots x Higgsfield
- TechCrunch: The internet is convinced xAI trolled OpenAI's dots launch
Andrew Lovesey is the editor-in-chief of prompt/power and the founder of Loveseyland, a Toronto studio that builds worlds and the companies inside them. Before that he spent 12 years at Canadian Geographic and the Royal Canadian Geographical Society, finishing as Director of Digital and Video, and later led the digital practice at Navigator. He is a Fellow of the RCGS and received its Quest Medal for his part in the expedition that located the wreck of Shackleton's Endurance. At prompt/power he covers Apple and writes the big-picture analysis. He has helped find a ship lost for more than a century, and still can't reliably find a phone charger that works.
Latest from prompt/power
- How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
- OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
- When an AI Agent Breaks In, Who Answers for It?Oct 5
- The New AI Models Don’t Talk. They Decide.Oct 5
- Quebec’s First AI Election: ChatGPT Leaned on an AI-Built Voter GuideOct 5
Leave a Reply